Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Trovebox version <= 4.0.0-rc6 contains a SQL Injection vulnerability in album component that can result in SQL code injection. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trovebox album组件SQL注入漏洞
Vulnerability Description
Trovebox是一套开源的图片共享和管理平台。album是其中的一个相册组件。 Trovebox 4.0.0-rc6之前版本中的album组件存在SQL注入漏洞。远程攻击者可通过发送HTTP请求利用该漏洞查看、添加、修改或删除后端数据库上的信息。
CVSS Information
N/A
Vulnerability Type
N/A